Really clear breakdown, especially the part on bulletproof hosting and the /24 expansion. One thing that pairs nicely with ASN pivoting is doing the same on the domain side: take a confirmed bad domain, pull the registrant email, NS, MX and CNAME it shares with other domains, and you usually surface a whole cluster before it shows up in public reports. We use that seed-and-pivot approach for the WhoisFreaks threat intelligence feeds (whoisfreaks.com/products/threat-intelligence-feed). Each record carries a confidence score and the number of matched pivots, and there are separate IP feeds for VPN, proxy, Tor, bot and C2. Looking forward to your domain analysis post, curious how you approach WHOIS privacy redaction when pivoting.